Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 175

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Warren Buffett's Berkshire Hathaway nailed the timing on Alphabet — whether by design or not
Married millennials, here comes the crypto divorce cliff
Southwest CEO says airline 'actively pursuing' network of airport lounges
Need money fast? These 4 cash-advance apps can help — but they're not risk-free
Trump trade rep changes China soybean purchase timeline, cites 'discrepancy'
Rivian turns to AI, autonomy to woo investors as EV sales stall
Cisco's stock closes at record for first time since dot-com peak in 2000
What December's Fed rate cut means for your mortgage, credit card, auto loan, student debt and savings
Why the stock market rallied so much on the Fed. Time to bet on a year-end melt up?
Trump says U.S. seized oil tanker off the coast of Venezuela